AI-Based Ensemble Learning Framework For Cyber Threat Detection And Response
Main Article Content
Abstract
The rapid digitization of critical services in India has significantly expanded the cyber-attack surface, rendering traditional security mechanisms inadequate against sophisticated modern threats. This paper presents a comprehensive AI-Based Ensemble Learning Framework for cyber threat detection and response, specifically designed to address the unique challenges of the Indian cybersecurity ecosystem. The framework integrates four complementary models—Random Forest, XGBoost, Deep Neural Networks (DNN), and Long Short-Term Memory (LSTM) networks—through a stacking ensemble approach with Logistic Regression as the meta-learner [27], [28], [30], [31]. Evaluation across four standard benchmark datasets—CIC-IDS2017, UNSW-NB15, NSL-KDD, and ICSCASD-MPLC—demonstrates detection accuracy ranging from 93% to 98% with false positive rates as low as 1.6% [23]-[26]. The system achieves near real-time performance with an average detection latency of 112 ms, substantially improving upon traditional Security Operations Center (SOC) metrics: mean time to detect (MTTD) reduced from 8-24 hours to 10-30 minutes, mean time to respond (MTTR) reduced from 24-72 hours to 15-60 minutes, and alert volume reduced from over 100,000 to 2,000-5,000 alerts per day [4], [17], [19]. The framework's performance on Industrial Control System (ICS) data is particularly encouraging, achieving 97.2% accuracy, addressing a critical gap in critical infrastructure protection [26], [35]. This work contributes a practical, deployable solution for modernizing cybersecurity operations in resource-constrained environments.
Downloads
Article Details
Section

This work is licensed under a Creative Commons Attribution 4.0 International License.
This work is licensed under a Creative Commons Attribution 4.0 International (CC BY 4.0) License. Authors retain the copyright of their work and grant the Journal of Global Research in Multidisciplinary Studies (JGRMS) the right of first publication. This license permits unrestricted use, distribution, adaptation, and reproduction in any medium or format, provided the original author(s), source, and publication are properly credited. Users may copy, redistribute, remix, transform, and build upon the published material for any purpose, including commercial use, in accordance with the terms of the CC BY 4.0 License.
How to Cite
References
[1]. CERT-In. "Annual reports and Guidelines for Protection of Critical Information Infrastructure." Government of India.
[2]. K. Achuthan, S. Ramanathan, S. Srinivas, and R. Raman, "Advancing cybersecurity and privacy with artificial intelligence: current trends and future research directions," Frontiers in Big Data, 2024. DOI: https://doi.org/10.3389/fdata.2024.1497535
[3]. "AutoCTI: Automated Cyber Threat Detection Using AutoML," IEEE Xplore, 2026.
[4]. "LSTM Autoencoder for Intrusion Detection: Performance evaluation on CICIDS2017 dataset," Elsevier, 2022.
[5]. (ISC)², "Cybersecurity Workforce Study," International Information System Security Certification Consortium, various years.
[6]. "HHO-GWO Feature Selection with Stacking Ensemble: Hybrid optimisation for intrusion detection," Applied Soft Computing, 2023.
[7]. "Cybersecurity Risk Assessment Models for Renewable Energy Integration in Smart Power Systems," IEEE DELCON, 2025.
[8]. Data Security Council of India (DSCI), "India Cyber Risk Report," various years.
[9]. "Optimised Random Forest Framework for Intrusion Detection: Feature selection and hyperparameter tuning on CIC-IDS2017," Expert Systems with Applications, 2024.
[10]. NetGuard-X: A Lightweight XGBoost Framework for Real-Time Network Intrusion Detection," Future Generation Computer Systems, 2023.
[11]. "DNN and RNN for Intrusion Detection: A Comparative Study," Journal of Network and Computer Applications, 2023.
[12]. "LSTM-Based Intrusion Detection System: A Comprehensive Evaluation," IEEE Transactions on Information Forensics and Security, 2023.
[13]. "Systematic Literature Review on Ensemble Learning for Intrusion Detection," ACM Computing Surveys, 2024.
[14]. "HAMC-ID: A Two-Level Stacking Ensemble Framework for Intrusion Detection," Information Sciences, 2024.
[15]. "Deep Learning for Industrial Control System Security: A Survey," IEEE Transactions on Industrial Informatics, 2024.
[16]. "The role of machine and deep learning in modern intrusion detection systems: A comprehensive review," ScienceDirect, 2025.
[17]. M.Y. Darus et al., "Cybersecurity Resilience — An Integrated Framework for Detection of Threats and Response," MJoC, 2025. DOI: https://doi.org/10.24191/mjoc.v10i1.4520
[18]. "AgentSOC: A Multi-Layer Agentic AI Framework for Security Operations Automation," arXiv, 2026.
[19]. "Morpheus (AI SOC) vs. Traditional SOAR," D3 Security, 2026.
[20]. M. Araujo, "Governing Adversarially Robust Artificial Intelligence in Critical Infrastructure Security Operations," ISJM, 2026. DOI: https://doi.org/10.56238/isevmjv5n3-015
[21]. N. Khan et al., "Explainable AI-based Intrusion Detection System for Industry 5.0," arXiv, 2024. DOI: https://doi.org/10.3390/info16121036
[22]. "Dual-Brain Architecture: The Cybersecurity AI Innovation That Changes Everything," Cyble Blog, 2026.
[23]. I. Sharafaldin, A.H. Lashkari, and A.A. Ghorbani, "Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization," ICISSP, 2018. DOI: https://doi.org/10.5220/0006639801080116
[24]. N. Moustafa and J. Slay, "UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems," MILCOM, 2015. DOI: https://doi.org/10.1109/MilCIS.2015.7348942
[25]. M. Tavallae, E. Bagheri, W. Lu, and A.A. Ghorbani, "A Detailed Analysis of the KDD CUP 99 Data Set," IEEE CISDA, 2009. DOI: https://doi.org/10.1109/CISDA.2009.5356528
[26]. A. Houkan et al., "Artificial intelligence approach to intrusion detection in industrial control systems with real world dataset generation and model evaluation," Discover Artificial Intelligence, vol. 5, p. 307, 2025. DOI: https://doi.org/10.1007/s44163-025-00507-2
[27]. L. Breiman, "Random Forests," Machine Learning, vol. 45, no. 1, pp. 5-32, 2001. DOI: https://doi.org/10.1023/A:1010933404324
[28]. T. Chen and C. Guestrin, "XGBoost: A Scalable Tree Boosting System," KDD, 2016. DOI: https://doi.org/10.1145/2939672.2939785
[29]. Y. LeCun, Y. Bengio, and G. Hinton, "Deep learning," Nature, vol. 521, no. 7553, pp. 436-444, 2015. DOI: https://doi.org/10.1038/nature14539
[30]. S. Hochreiter and J. Schmidhuber, "Long Short-Term Memory," Neural Computation, vol. 9, no. 8, pp. 1735-1780, 1997. DOI: https://doi.org/10.1162/neco.1997.9.8.1735
[31]. D.H. Wolpert, "Stacked Generalization," Neural Networks, vol. 5, no. 2, pp. 241-259, 1992. DOI: https://doi.org/10.1016/S0893-6080(05)80023-1
[32]. I. Goodfellow, J. Shlens, and C. Szegedy, "Explaining and Harnessing Adversarial Examples," ICLR, 2015.
[33]. A. Madry et al., "Towards Deep Learning Models Resistant to Adversarial Attacks," ICLR, 2018.
[34]. S. Lundberg and S.I. Lee, "A Unified Approach to Interpreting Model Predictions," NeurIPS, 2017.
[35]. CERT-In, "Guidelines for Protection of Critical Information Infrastructure," Government of India.
[36]. V. Misal, V. P. Janeja, S. C. Pallaprolu, Y. Yesha, and R. Chintalapati, “Iterative unified clustering in big data,” in 2016 IEEE International Conference on Big Data (Big Data), Washington, DC, USA: IEEE, Dec. 2016, pp. 3412–3421. doi: 10.1109/BigData.2016.7841002. DOI: https://doi.org/10.1109/BigData.2016.7841002
[37]. S. Sreevathsa, “Strategies for Reducing Alert Fatigue and Improving Signal Quality in Enterprise Monitoring Architectures,” Int. J. Adv. Eng. Manag. Sci., vol. 12, no. 3, pp. 444–451, May-Jun, 2026, doi: https://dx.doi.org/10.22161/ijaems.123.42. DOI: https://doi.org/10.22161/ijaems.123.42
[38]. S. Remella et al., “Intelligent Cost Governance in Cloud Supply Chains,” in 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), Belagavi, India: IEEE, 2025, pp. 1–7, December. doi: 10.1109/ICAFT66710.2025.11452715. DOI: https://doi.org/10.1109/ICAFT66710.2025.11452715
[39]. S. Remella, J. Ligam, U. K. R. Gangula, V. Sannamuri, R. Ganta, and Q. T. Sadat, “End-to-End Cloud Procurement Lifecycle Automation,” in 2025 1st International Conference on Advancement in Futuristic Technologies (ICAFT), Belagavi, India: IEEE, 2025, pp. 1–8. doi: 10.1109/ICAFT66710.2025.11452870. DOI: https://doi.org/10.1109/ICAFT66710.2025.11452870
[40]. M. R. C. Mukkolakkal, “Deploy, Calibrate, Monitor, Heal -- No Human Required: An Autonomous AI SRE Agent for Elasticsearch,” arvix.org, Apr. 2026.
[41]. S. Chatterjee, “Advanced Malware Detection in Operational Technology: Signature-Based Vs. Behaviour-Based Approaches,” ESP J. Eng. Technol. Adv., vol. 1, 2021, doi: 10.56472/25832646/JETA-V1I2P128